Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in XWiki platform - CVE-2023-45134

 

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in XWiki platform - CVE-2023-45134

Published: October 25, 2023 / Updated: May 5, 2026


Vulnerability identifier: #VU129915
CSH Severity: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2023-45134
CWE-ID: CWE-80
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
XWiki platform
Software vendor:
XWiki

Description

The vulnerability allows a remote user to execute arbitrary actions with the rights of the user opening a malicious link.

The vulnerability exists due to improper neutralization of script-related HTML tags in the create page form via template provider when processing a selected template provider during document creation. A remote user can create a malicious template provider and send a crafted URL to execute arbitrary actions with the rights of the user opening a malicious link.

User interaction is required to open the crafted link, and exploitation depends on the privileges of the user who opens it.


Remediation

Install security update from vendor's website.

External links